Skip to main content
robinct
New Member
August 27, 2019
Question

FortiGate SSO users using RODC

  • August 27, 2019
  • 4 replies
  • 5600 views

I'm at initial setup of FortiGate SSO. I'm currently using the option with an installed Collector Agent that are polling our DC's.

 

The problem comes when users are logging in to one of the RODC's, and the client are getting the workstation IP of the RODC, instead of their respective workstations.

 

Would installing DC agents solve this, or is there another way around this?

    4 replies

    xsilver_FTNT
    Staff
    Staff
    August 28, 2019

    I would try to put IP addresses of RODC servers to FSSO registry key "dc_agent_ignore_ip_list" of Collector.

    Which supposed to be )on 64bit system) in [HKEY_LOCAL_MACHINE\software\WOW6432Node\fortinet\fsae\collectoragent]

    robinct
    robinctAuthor
    New Member
    August 28, 2019

    xsilver wrote:

    I would try to put IP addresses of RODC servers to FSSO registry key "dc_agent_ignore_ip_list" of Collector.

    Which supposed to be )on 64bit system) in [HKEY_LOCAL_MACHINE\software\WOW6432Node\fortinet\fsae\collectoragent]

    Thanks. Found the key. Tested briefly for a couple of hours, and the only difference seems to be that the users aren't being registered at all now. I will leave it running for a while longer

    xsilver_FTNT
    Staff
    Staff
    August 28, 2019

    There is KB https://kb.fortinet.com/kb/documentLink.do?externalID=FD36364 and old blog post of MSFT on how RODC works .. https://blogs.technet.microsoft.com/askds/2008/01/18/understanding-read-only-domain-controller-authentication/ It's a bit old post but I guess that there is not much of a new stuff since then.

     

    So, as RODC is basically cache for logons and read-only, then if user authenticates locally, it might NOT generate any event, but if user is not cached (pre-cached as described in MSFT post) then logon is proxied from RODC to writable DC. And as originator is RODC then I gues sthis is reason why writable DC has RODC as 'workstation' where user logged in. Pre-cached passwords on RODC via admin action and then kept by password replication policy might help.

    I'm referring to part: "When a user authenticates to an RODC a check is performed to see if the password is cached. If the password is cached, the RODC will authenticate the user account locally. If the user’s password is not cached, then the RODC forwards the authentication request to a writable Windows Server 2008 Domain Controller which in turn authenticates the account and passes the authenticated request back to the RODC."

    FrancoisBlanchon
    Visitor III
    May 20, 2022

    Hi Guys,

    I am currently assisting my customer for FSSO implementation. To be honest I do not clearly understand this thread. Should I install DC Agent on RODC or not ? will I be able to get the users logon's information from remote small sites with local RODC ? With their real IPs or with the useless RODC IP address ?

    If someone can clarify this point it could be great.

    Thanks a lot.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!